WordPress plugin profile

SiteGuard Scanner

Companion plugin for the EG Secure Solutions vulnerability diagnostic service: signed site-ownership verification and plugin/theme inventory.

Updated 4h ago·New active installs·★ 0.0
Version1.0.0
Tested toWP 7.1
Requires WP5.0
Requires PHP7.4
Overview

About this plugin

SiteGuard Scanner is a companion plugin for the vulnerability diagnostic service provided by EG Secure Solutions. Installing it on a site that is under a diagnostic contract enables the following two features. Site ownership verification (authentication) — Lets the diagnostic service confirm that the target site is the one that is actually under a diagnostic contract. Installation inventory — Provides the diagnostic service with a list of the plugins and themes installed on the target site (name, version, and activation status). How it communicates The plugin only responds to signed requests sent by the diagnostic service. It never sends data to any external server on its own (it does not “phone home”). Authentication uses an HMAC-SHA256 signature based on a shared token. Each request includes a timestamp and a nonce (a single-use random value) to prevent replay attacks. Requests are received through the WordPress REST API endpoints /wp-json/siteguard-scanner/v1/verify and /wp-json/siteguard-scanner/v1/collect . For environments where the REST API is disabled, a custom endpoint ( /?siteguard-scanner-request=verify and /?siteguard-scanner-request=collect ) is provided as a fallback. Every endpoint responds only to requests carrying a valid signature. When signature verification fails, the plugin returns HTTP 401 and no information at all. Data provided When responding to collect , the plugin returns the following information to the diagnostic service: Site URL WordPress core version List of installed plugins (slug, name, version, activation status, network-activation status) List of installed themes (slug, name, version, activation status, network-enabled status) No personal data, post content, or any other data beyond the above is collected or transmitted. Multisite On a multisite network, diagnostics are performed against the main (parent) site. Because plugin and theme files are shared across the entire network, collect returns the network-wide inventory of installed assets and correctly reports network-activated plugins via the network_active flag.